www.molinoag.com - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.molinoag.com and returned a suspicious verdict (score 32), categorised as credential-harvest. The page resolved to 134.0.9.99 on CDmon in ES. The domain was registered 8487 days ago through Nominalia Internet SL. 20 domains and 1 IP were contacted, over 15 HTTP requests. 7 malware samples communicate with this URL (Phishing). The request followed 2 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 32) · Confidence 35%
- Scanned URL:
http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160acbe891e4fa---xubumunoloxamavadatexan.pdf - Domain: www.molinoag.com · IP: 134.0.9.99 · AS197712 · ES
- Server: Apache
- Page title: Solucions d'impressió comercial per a empreses | Molino Arts Gràfiques
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Nominalia Internet SL · domain age 8487 days · created 2003-05-27
- HTTP requests captured: 15
- Scan tier: fast · observed 2026-08-22 03:01:42 UTC
Redirect chain
http://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160acbe891e4fa---xubumunoloxamavadatexan.pdfhttps://www.molinoag.com/wp-content/plugins/formcraft/file-upload/server/content/files/160acbe891e4fa---xubumunoloxamavadatexan.pdfhttps://www.molinoag.com/
Malware communicating with this URL (7)
These samples were observed contacting or being served from www.molinoag.com. Each links to its full analysis.
- Phishing - referenced ·
09eed28d791f2ca1031d8b535d346707· first seen 2026-08-22 - Phishing - referenced ·
00ea972dc577753423e60a9558209e36· first seen 2026-08-21 - Phishing - referenced ·
35a23f4ce50f7d6b5fc392a14e17959c· first seen 2026-08-16 - Phishing - referenced ·
65b8b9a8b6ea88287212fe8d6f17e896· first seen 2026-08-15 - Phishing - referenced ·
83acf104d83b6aa98a6836f58a8e884d· first seen 2026-08-13 - Phishing - referenced ·
ab2529cd888f9b208b0d218ae4c2714b· first seen 2026-08-13 - Phishing - referenced ·
6b9c7c77de41a30aae29f9dbc5683cbf· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 134.0.9.99 - AS197712 CDmon (Spain)
Observed indicators
- www.molinoag.com
- fonts.gstatic.com
- fonts.googleapis.com
- cdn.jsdelivr.net
- cdnjs.cloudflare.com
- www.facebook.com
- consent.cookiebot.com
- www.linkedin.com
- www.instagram.com
- generalcatalogue2026.eu
- catalog.on-catalogue.com
- catalogue.sologroup-paris.com
- resources.jhktshirt.com
- issuu.com
- shop.molinoag.com
- molinoag.us6.list-manage.com
- www.xtrategics.com
- code.jquery.com
- www.googletagmanager.com
- www.google.com
Other scans of www.molinoag.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 13 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious
Questions about www.molinoag.com
- Is www.molinoag.com safe?
- No. MalwareAnalyzer scanned www.molinoag.com on 22 Aug 2026 and returned a suspicious verdict with a score of 32 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.molinoag.com?
- 7 analysed samples communicate with this URL, including Phishing.
- How was www.molinoag.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.molinoag.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan